Menu

#64 Security Vulnerability

v0.9.5
open
nobody
RDQL (2)
5
2008-07-08
2008-07-08
Anonymous
No

Class RdqlDbEngine uses an eval statement during filtering that allows malicious php code to be run as the PHP user. Line 318. Examples are trivial, and are not posted here.
Filters should be rewritten to use MySQL or other DB equivalents.

Discussion

Want the latest updates on software, tech news, and AI?
Get latest updates about software, tech news, and AI from SourceForge directly in your inbox once a month.